The Experts below are selected from a list of 162 Experts worldwide ranked by ideXlab platform
Peng Liu - One of the best experts on this subject based on the ideXlab platform.
-
From Database to Cyber security - Retrieval of Relevant Historical Data Triage operations in security Operation centers
Lecture Notes in Computer Science, 2018Co-Authors: Tao Lin, Chen Zhong, John Yen, Peng LiuAbstract:Triage analysis is a fundamental stage in cyber operations in security operations centers (SOCs). The massive data sources generate great demands on cyber security analysts’ capability of information processing and analytical reasoning. Furthermore, most junior security analysts perform much less efficiently than senior analysts in deciding what data triage operations to perform. To help (junior) analysts perform better, several retrieval methods have been proposed to facilitate data triaging through retrieval of the relevant historical data triage operations of senior security analysts. This paper conducts a review of the existing retrieval methods, including rule-based retrieval and context-based retrieval of data triage operations. It further discusses the new directions in solving the data triage operation retrieval problem.
-
retrieval of relevant historical data triage operations in security operation centers
From Database to Cyber Security, 2018Co-Authors: Tao Lin, Chen Zhong, John Yen, Peng LiuAbstract:Triage analysis is a fundamental stage in cyber operations in security operations centers (SOCs). The massive data sources generate great demands on cyber security analysts’ capability of information processing and analytical reasoning. Furthermore, most junior security analysts perform much less efficiently than senior analysts in deciding what data triage operations to perform. To help (junior) analysts perform better, several retrieval methods have been proposed to facilitate data triaging through retrieval of the relevant historical data triage operations of senior security analysts. This paper conducts a review of the existing retrieval methods, including rule-based retrieval and context-based retrieval of data triage operations. It further discusses the new directions in solving the data triage operation retrieval problem.
Natalia Miloslavskaya - One of the best experts on this subject based on the ideXlab platform.
-
analysis of siem systems and their usage in security operations and security intelligence centers
Biologically Inspired Cognitive Architectures, 2017Co-Authors: Natalia MiloslavskayaAbstract:To achieve business objectives, to stay competitive and to operate legally modern organizations of all types (e.g. commercial enterprises, government agencies, not-for profit organizations), different size and sphere of activity need to match a lot of internal and external requirements. They are called compliance regulations and mean conforming to a rule, such as a specification, procedure, policy, standard, law, etc. These organizations need to ensure valuable assets, uninterrupted business operation (processes), reliable data and differentiated quality of service (QoS) to various groups of users. They need to protect their clients and employees not only inside but also outside organization itself in connection with which two new terms were introduced – teleworking or telecommuting. According to Gartner by 2020, 30% of global enterprises will have been directly compromised by an independent group of cybercriminals or cyberactivists. And in 60% of network breaches, hackers compromise the network within minutes, says Verizon in the 2015 Data Breach Investigations Report. An integrated system to manage organizations’ intranet security is required as never before. The data collected and analyzed within this system should be evaluated online from a viewpoint of any information security (IS) incident to find its source, consider its type, weight its consequences, visualize its vector, associate all target systems, prioritize countermeasures and offer mitigation solutions with weighted impact relevance. The brief analysis of a concept and evolution of security Information and Event Management (SIEM) systems and their usage in security operations centers and security Intelligence centers for intranet’s IS management are presented.
-
soc and sic based information security monitoring
World Conference on Information Systems and Technologies, 2017Co-Authors: Natalia MiloslavskayaAbstract:New numerous and sophisticated attacks make organizations’ IT infrastructure (ITI) break-in more professional and dangerously effective. The organizations must oppose this properly designed and centralized information security (IS) incident management system. Learn from the past helps to avoid the consequences of serious IS incidents in the future. Therefore, IS monitoring is necessary for rapidly detecting IS incidents, minimizing loss and destruction, mitigating the vulnerabilities exploited and restoring organization’s ITI. This process can be implemented based on security operations centers (SOCs) and security Intelligence centers (SICs) as their next evolution step. SOCs’ main functions and serious limitations are defined. The SICs’ concept and functioning are analyzed. The main ideas of further research conclude the paper.
-
WorldCIST (2) - SOC- and SIC-Based Information security Monitoring
Advances in Intelligent Systems and Computing, 2017Co-Authors: Natalia MiloslavskayaAbstract:New numerous and sophisticated attacks make organizations’ IT infrastructure (ITI) break-in more professional and dangerously effective. The organizations must oppose this properly designed and centralized information security (IS) incident management system. Learn from the past helps to avoid the consequences of serious IS incidents in the future. Therefore, IS monitoring is necessary for rapidly detecting IS incidents, minimizing loss and destruction, mitigating the vulnerabilities exploited and restoring organization’s ITI. This process can be implemented based on security operations centers (SOCs) and security Intelligence centers (SICs) as their next evolution step. SOCs’ main functions and serious limitations are defined. The SICs’ concept and functioning are analyzed. The main ideas of further research conclude the paper.
-
FiCloud Workshops - security Intelligence centers for Big Data Processing
2017 5th International Conference on Future Internet of Things and Cloud Workshops (FiCloudW), 2017Co-Authors: Natalia MiloslavskayaAbstract:Today numerous information security (IS) incidents in organizations' networks have become not only more sophisticated but also damaging. Hence the systems with proper security services in place to mitigate and promptly respond to IS threats by helping organizations better understand their current network situation, as well as to perform routine work in big IS-related data processing in automatic mode are needed as never before. They are known as security operations centers (SOCs) and security Intelligence centers (SICs) as their next evolution step. The key features of SICs are summarized. The SIC business logic and data architecture are proposed. These results lead to the main area of further research.
-
security operations centers for information security incident management
Conference on the Future of the Internet, 2016Co-Authors: Natalia MiloslavskayaAbstract:At present information security (IS) incidents have become not only more numerous and diverse but also more damaging and disruptive. Preventive controls based on the IS risk assessment results decrease the majority but not all the IS incidents. Therefore, an IS incident management system is necessary for rapidly detecting IS incidents, minimizing loss and destruction, mitigating the vulnerabilities that were exploited and restoring the Internet of Things infrastructure (IoTI), including its IT services. These systems can be implemented on the basis of a security operations Center (SOC). Based on the related works a survey of the existing SOCs, their mission and main functions is given. The SOCs' classification as well as the key indicators of IS incidents in IoTI are proposed. Some serious first-generation SOCs' limitations are defined. This analysis leads to the main area of further research launched by the author.
Tao Lin - One of the best experts on this subject based on the ideXlab platform.
-
From Database to Cyber security - Retrieval of Relevant Historical Data Triage operations in security Operation centers
Lecture Notes in Computer Science, 2018Co-Authors: Tao Lin, Chen Zhong, John Yen, Peng LiuAbstract:Triage analysis is a fundamental stage in cyber operations in security operations centers (SOCs). The massive data sources generate great demands on cyber security analysts’ capability of information processing and analytical reasoning. Furthermore, most junior security analysts perform much less efficiently than senior analysts in deciding what data triage operations to perform. To help (junior) analysts perform better, several retrieval methods have been proposed to facilitate data triaging through retrieval of the relevant historical data triage operations of senior security analysts. This paper conducts a review of the existing retrieval methods, including rule-based retrieval and context-based retrieval of data triage operations. It further discusses the new directions in solving the data triage operation retrieval problem.
-
retrieval of relevant historical data triage operations in security operation centers
From Database to Cyber Security, 2018Co-Authors: Tao Lin, Chen Zhong, John Yen, Peng LiuAbstract:Triage analysis is a fundamental stage in cyber operations in security operations centers (SOCs). The massive data sources generate great demands on cyber security analysts’ capability of information processing and analytical reasoning. Furthermore, most junior security analysts perform much less efficiently than senior analysts in deciding what data triage operations to perform. To help (junior) analysts perform better, several retrieval methods have been proposed to facilitate data triaging through retrieval of the relevant historical data triage operations of senior security analysts. This paper conducts a review of the existing retrieval methods, including rule-based retrieval and context-based retrieval of data triage operations. It further discusses the new directions in solving the data triage operation retrieval problem.
John Yen - One of the best experts on this subject based on the ideXlab platform.
-
From Database to Cyber security - Retrieval of Relevant Historical Data Triage operations in security Operation centers
Lecture Notes in Computer Science, 2018Co-Authors: Tao Lin, Chen Zhong, John Yen, Peng LiuAbstract:Triage analysis is a fundamental stage in cyber operations in security operations centers (SOCs). The massive data sources generate great demands on cyber security analysts’ capability of information processing and analytical reasoning. Furthermore, most junior security analysts perform much less efficiently than senior analysts in deciding what data triage operations to perform. To help (junior) analysts perform better, several retrieval methods have been proposed to facilitate data triaging through retrieval of the relevant historical data triage operations of senior security analysts. This paper conducts a review of the existing retrieval methods, including rule-based retrieval and context-based retrieval of data triage operations. It further discusses the new directions in solving the data triage operation retrieval problem.
-
retrieval of relevant historical data triage operations in security operation centers
From Database to Cyber Security, 2018Co-Authors: Tao Lin, Chen Zhong, John Yen, Peng LiuAbstract:Triage analysis is a fundamental stage in cyber operations in security operations centers (SOCs). The massive data sources generate great demands on cyber security analysts’ capability of information processing and analytical reasoning. Furthermore, most junior security analysts perform much less efficiently than senior analysts in deciding what data triage operations to perform. To help (junior) analysts perform better, several retrieval methods have been proposed to facilitate data triaging through retrieval of the relevant historical data triage operations of senior security analysts. This paper conducts a review of the existing retrieval methods, including rule-based retrieval and context-based retrieval of data triage operations. It further discusses the new directions in solving the data triage operation retrieval problem.
Chen Zhong - One of the best experts on this subject based on the ideXlab platform.
-
From Database to Cyber security - Retrieval of Relevant Historical Data Triage operations in security Operation centers
Lecture Notes in Computer Science, 2018Co-Authors: Tao Lin, Chen Zhong, John Yen, Peng LiuAbstract:Triage analysis is a fundamental stage in cyber operations in security operations centers (SOCs). The massive data sources generate great demands on cyber security analysts’ capability of information processing and analytical reasoning. Furthermore, most junior security analysts perform much less efficiently than senior analysts in deciding what data triage operations to perform. To help (junior) analysts perform better, several retrieval methods have been proposed to facilitate data triaging through retrieval of the relevant historical data triage operations of senior security analysts. This paper conducts a review of the existing retrieval methods, including rule-based retrieval and context-based retrieval of data triage operations. It further discusses the new directions in solving the data triage operation retrieval problem.
-
retrieval of relevant historical data triage operations in security operation centers
From Database to Cyber Security, 2018Co-Authors: Tao Lin, Chen Zhong, John Yen, Peng LiuAbstract:Triage analysis is a fundamental stage in cyber operations in security operations centers (SOCs). The massive data sources generate great demands on cyber security analysts’ capability of information processing and analytical reasoning. Furthermore, most junior security analysts perform much less efficiently than senior analysts in deciding what data triage operations to perform. To help (junior) analysts perform better, several retrieval methods have been proposed to facilitate data triaging through retrieval of the relevant historical data triage operations of senior security analysts. This paper conducts a review of the existing retrieval methods, including rule-based retrieval and context-based retrieval of data triage operations. It further discusses the new directions in solving the data triage operation retrieval problem.